AI governance for banks and financial services

    In financial services, the AI Act is neither the only reference nor the first one in place. It builds on an existing supervisory framework, and the challenge is not understanding each rule in isolation but making overlapping obligations work across different processes.

    The regulatory framework

    • AI Act, Annex III: assessment of the creditworthiness of natural persons is classified as high risk, with obligations applying from 2 December 2027 following the Digital Omnibus postponement
    • DORA, for digital operational resilience and the management of critical third-party providers
    • EBA guidelines on internal governance and model risk management
    • GDPR, for automated decisions that produce legal effects on individuals
    • ISO/IEC 42001, as a voluntary method for bringing the preceding requirements together

    Use cases and their risk level

    Use caseClassificationNote
    Credit scoring of natural personsHigh risk, Annex IIIFull obligations for data, documentation and human oversight
    Anti-money laundering and fraud detectionAssess case by caseDepends on purpose and impact on the individual
    Customer-facing conversational assistantsLimited riskArticle 50 transparency obligations, already in force
    Market risk modelsOutside Annex IIIExisting prudential requirements still apply
    Internal productivity toolsMinimal riskThey should still be included in the inventory

    Where to start

    1. 1Build an AI system inventory based on purpose rather than tool, because the same model used in two processes can have two different classifications
    2. 2Verify the role assumed for each system, provider or deployer: fine-tuning on proprietary data may place the bank among providers under Article 25
    3. 3Align existing model risk management with AI Act requirements instead of building a second parallel framework

    What we do for the sector

    The path is always the same and the content changes: it starts from the use case map, assesses impact before investing, validates with a prototype, and only then reaches production. Rapid prototyping runs through protot.ai, our validation unit.

    1

    Use case definition

    We map the processes where AI produces value and those where it only adds risk, distinguishing by purpose rather than by tool: the same model used in loan processing and in marketing campaigns carries two different classifications. The output is a prioritised use case portfolio, each with its risk class and the role the bank assumes.

    2

    Impact assessment

    For every use case in the portfolio we measure expected economic impact and impact on people, which for Annex III systems is also a regulatory obligation. The Value Case always compares the AI option against the non-AI alternative, and when the latter wins we say so.

    3

    Prototyping and validation

    With protot.ai we build a working prototype on real data within weeks, to test the hypothesis before committing project budget. In credit, that means testing against a historical sample whether the model meets acceptance thresholds defined beforehand rather than afterwards.

    4

    Production and oversight

    When the prototype confirms the hypothesis we support the move to production: integration with portfolio systems, event logging consistent with Article 12, human oversight designed in rather than bolted on, technical documentation. Then ongoing oversight remains, because a model whose behaviour shifts needs reassessment.

    Assess your organisation's starting point